An unauthenticated attacker may connect and operate the affected robot.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated WebSocket Control of Ecovacs Deebot Robots |
Mon, 10 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot. | |
| Weaknesses | CWE-303 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-08-10T08:13:34.748Z
Reserved: 2026-07-27T00:45:20.457Z
Link: CVE-2026-66411
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T10:45:03Z